Frequency
3
occurrences
First Seen
April 30, 2026
Last Seen
May 5, 2026
Related Threat Clusters
-
SHADOW-EARTH-053 Exploits Microsoft Exchange Vulnerabilities in Asia
The China-aligned threat group SHADOW-EARTH-053 has been exploiting unpatched Microsoft Exchange and IIS server vulnerabilities, specifically the ProxyLogon vulnerability chain, to conduct cyberespionage. This group has…
2 articles · Updated May 5, 2026 -
Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
381 articles · Updated April 2, 2026
Recent Intelligence Reports
- SHADOW-EARTH-053 Targets Exchange Servers in Asia — Socprime · May 5, 2026
- Chinese spy group caught lurking in Poland, Asia networks — Theregister · April 30, 2026
- What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia — Theregister · April 30, 2026